Sign-in security: two-factor, email links and session length
Choose how members sign in, who must use two-factor authentication, how long a session lasts and which email domains may join.
This article is for the administrators who run an organisation's Portava portal.
In short
- Sign-in methods and requirements are one card under Portal settings, then General.
- Two-factor can be required for nobody, for your team, or for everyone. Nobody is locked out while they set it up.
- Operations, then Security shows the same settings and who on your team has an authenticator app.
Your sign-in policy lives in the Sign-in card under Portal settings, then General. It is saved as one form, so you can see what stays on when you turn something off. At least one sign-in method must stay on.
Sign-in methods
- Email and password is the standard sign-in.
- Sign in with Google lets members with a Google account skip the password. It is only offered once the Portava team has set Google up for the platform. Until then the row reads Not set up.
- Email link sends a one-time sign-in link. It is not offered to members using two-factor authentication, because a link would bypass their code.
These switches shape your sign-in page. They do not change anyone’s account.
Requiring two-factor authentication
Choose Not required, Administrators and content managers, or Everyone. Anyone covered is asked to set up an authenticator app before they can enter the portal. They are guided through it step by step and are never locked out. A member of more than one portal only sets it up once.
Session timeout
Members are signed out and asked to sign in again after this long. The choices are the platform default of 7 days, or 1 hour, 8 hours, 24 hours or 3 days. A shorter limit suits shared computers.
Restricting new members to email domains
List domains, separated by commas, and invitations and self sign-up will only accept addresses on them. Leave it empty for no restriction. Existing members are unaffected. This narrows who can join; it never admits anyone by itself.
Where the posture shows
Operations, then Security repeats these settings in the same words, and shows how many of your administrators and content managers have an authenticator app set up, how many administrator invitations are still open, and how many of the team are signed in now.